CWE-693

CWE-693 · 25 records · 17 with a public proof-of-concept

Records the NVD classes under CWE-693, highest CVSS first.

  1. CRITICAL 10CVE-2026-92956public PoC

    vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.9CVE-2026-92948public PoC

    vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, mo…

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.9CVE-2026-92938public PoC

    vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but …

    AI risk analysis on Exploit-DB.ai →

  4. CRITICAL 9.8CVE-2026-92944public PoC

    vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an a…

    AI risk analysis on Exploit-DB.ai →

  5. CRITICAL 9.6CVE-2026-20331

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has cond…

    AI risk analysis on Exploit-DB.ai →

  6. CRITICAL 9.1CVE-2026-39353public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlle…

    AI risk analysis on Exploit-DB.ai →

  7. CRITICAL 9CVE-2026-92934public PoC

    vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in hand…

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 8.8CVE-2026-92124

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attac…

    script security

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 8.8CVE-2026-92123

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scri…

    script security

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 8.8CVE-2026-92122

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowin…

    script security

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 8.4CVE-2026-76825public PoC

    RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library s…

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 8.2CVE-2026-100676public PoC

    January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who ca…

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 7.5CVE-2026-92129

    Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to byp…

    script security

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 7.1CVE-2026-92959public PoC

    vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve, Promise.all, Promise.…

    AI risk analysis on Exploit-DB.ai →

  15. MEDIUM 6.8CVE-2026-77401public PoC

    Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are …

    AI risk analysis on Exploit-DB.ai →

  16. MEDIUM 6.7CVE-2026-85288public PoC

    Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple Times entry point, calls macroPlayback() without the validation used by …

    AI risk analysis on Exploit-DB.ai →

  17. MEDIUM 6.5CVE-2026-94251

    A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes th…

    AI risk analysis on Exploit-DB.ai →

  18. MEDIUM 6.3CVE-2026-79919public PoC

    MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python i…

    AI risk analysis on Exploit-DB.ai →

  19. MEDIUM 6.3CVE-2026-79918public PoC

    MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool c…

    AI risk analysis on Exploit-DB.ai →

  20. MEDIUM 6.1CVE-2026-91796

    The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

    AI risk analysis on Exploit-DB.ai →

  21. MEDIUM 5.3CVE-2026-90950

    The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has…

    AI risk analysis on Exploit-DB.ai →

  22. LOW 3.5CVE-2025-71424public PoC

    Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially b…

    AI risk analysis on Exploit-DB.ai →

  23. UNSCOREDCVE-2026-101900public PoC

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw s…

    AI risk analysis on Exploit-DB.ai →

  24. UNSCOREDCVE-2026-54577public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such…

    AI risk analysis on Exploit-DB.ai →

  25. UNSCOREDCVE-2026-92962public PoC

    vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[lines.length] = value) r…

    AI risk analysis on Exploit-DB.ai →